Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenClaw — Vulnerabilities & Security Advisories 639

All 639 CVE vulnerabilities found in OpenClaw, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting OpenClaw, a software product, categorized by specific weakness types. It collects publicly disclosed security flaws, including buffer overflows, injection issues, and authentication bypasses, spanning the period from the product's initial release through the latest available advisories. Visitors can track the vendor's published security notices, analyze patterns within a specific weakness class, and review the complete historical record of vulnerabilities identified in OpenClaw. The data is organized to facilitate trend analysis and risk assessment, allowing security teams to identify recurring defect classes and evaluate the severity distribution over time. All entries are sourced from public vulnerability databases and official vendor bulletins, ensuring traceability and consistency in reporting standards. Users can filter results by date range, impact score, or component module to focus on relevant subsets of findings. The collection serves as a centralized reference for tracking how OpenClaw's security posture has evolved, supporting maintenance planning and compliance reporting without relying on scattered external sources.

Vendor: OpenClaw

CVE ID Title CVSS Severity Published
CVE-2026-53851 OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass CWE-862 5.3 Medium 2026-06-16
CVE-2026-53849 OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFrom CWE-290 8.1 High 2026-06-16
CVE-2026-53850 OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command CWE-862 5.5 Medium 2026-06-16
CVE-2026-53848 OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers CWE-184 4.3 Medium 2026-06-16
CVE-2026-53847 OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope CWE-266 5.4 Medium 2026-06-16
CVE-2026-53846 OpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env npm_execpath CWE-426 7.1 High 2026-06-16
CVE-2026-53845 OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook Skipping CWE-693 4.3 Medium 2026-06-16
CVE-2026-53844 OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search CWE-862 6.5 Medium 2026-06-16
CVE-2026-53843 OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device Session CWE-613 8.8 High 2026-06-16
CVE-2026-53842 OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment Variable CWE-426 7.1 High 2026-06-16
CVE-2026-53841 OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTML CWE-83 6.1 Medium 2026-06-16
CVE-2026-53840 OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects CWE-522 7.1 High 2026-06-16
CVE-2026-53839 OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation CWE-1023 6.5 Medium 2026-06-12
CVE-2026-53837 OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers CWE-636 3.7 Low 2026-06-12
CVE-2026-53838 OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection CWE-367 9.8 Critical 2026-06-12
CVE-2026-53836 OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases CWE-184 8.8 High 2026-06-12
CVE-2026-53835 OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings CWE-863 4.3 Medium 2026-06-12
CVE-2026-53834 OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands CWE-863 7.5 High 2026-06-12
CVE-2026-53833 QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command CWE-290 7.7 High 2026-06-12
CVE-2026-53832 OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration CWE-290 7.7 High 2026-06-12
CVE-2026-53831 OpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin Allowlist CWE-367 8.3 High 2026-06-12
CVE-2026-53830 OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload CWE-613 6.5 Medium 2026-06-12
CVE-2026-53829 OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display CWE-451 8.0 High 2026-06-12
CVE-2026-53827 OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.action Forwarding CWE-918 6.5 Medium 2026-06-12
CVE-2026-53828 OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement CWE-863 8.8 High 2026-06-12
CVE-2026-53826 OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn CWE-668 4.3 Medium 2026-06-12
CVE-2026-53825 OpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with operator.write Scope CWE-22 6.5 Medium 2026-06-12
CVE-2026-53824 Mattermost plugin for OpenClaw < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh Delay CWE-613 6.5 Medium 2026-06-12
CVE-2026-53823 OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom CWE-290 8.1 High 2026-06-12
CVE-2026-53821 OpenClaw < 2026.5.18 - Scope Elevation in trusted-proxy Control UI WebSocket CWE-862 8.8 High 2026-06-12

All 639 known CVE vulnerabilities affecting OpenClaw with full Chinese analysis, references, and POCs where available.